ASOM-Fedv6.1Open the explorer
Outcome index · National Institute of Standards and Technology

NIST Cybersecurity Framework 2.0

Six functions, twenty-two categories and 106 subcategories, each stating an outcome rather than a mechanism. Its subcategory identifiers have become the shared index agencies and vendors describe security outcomes in.

93/106Subcategories cited13 subcategories are claimed by nothing in the catalog, and every one of them is listed.
78Controls carrying itEach with an evidence artifact and an assessment procedure
4Stated boundariesWhat this framework does not do for this regime
The Claim

What This Framework Contributes.

The strongest crosswalk on this page and still a partial one: the catalog cites just over half the subcategory set, and the half it does not cite is listed by identifier rather than left as a gap the reader has to find.

The Boundary

What it does not do for CSF 2.0.

Read this before the crosswalk, not after it. A reader who takes the mappings below as coverage of CSF 2.0 will be wrong in a way that is expensive to discover later.

Coverage

Function by Function, Against the Published Set.

93 of the 106 subcategories in CSF 2.0 are claimed by at least one control. The distribution is lopsided and is published lopsided: Govern is cited through 22 of its 31 subcategories, and no claim of Govern coverage is made on the strength of it.

FunctionSubcategories claimedControls claiming themWhat the function asks for
GovernGV22 of 31 — 71%30 of 78The organization’s cybersecurity risk management strategy, expectations and policy are established, communicated and monitored.
IdentifyID19 of 21 — 90%37 of 78The organization’s current cybersecurity risks are understood — its assets, its suppliers, and the improvements its own operations reveal.
ProtectPR20 of 22 — 91%27 of 78Safeguards to manage the organization’s cybersecurity risks are used — access, training, data, platforms and infrastructure resilience.
DetectDE11 of 11 — 100%13 of 78Possible cybersecurity attacks and compromises are found and analyzed.
RespondRS13 of 13 — 100%12 of 78Actions regarding a detected cybersecurity incident are taken — management, analysis, communication and mitigation.
RecoverRC8 of 8 — 100%9 of 78Assets and operations affected by a cybersecurity incident are restored, and the restoration is communicated.

Govern

GV

Subcategories claimed
22 of 31 — 71%
Controls claiming them
30 of 78
What the function asks for
The organization’s cybersecurity risk management strategy, expectations and policy are established, communicated and monitored.

Identify

ID

Subcategories claimed
19 of 21 — 90%
Controls claiming them
37 of 78
What the function asks for
The organization’s current cybersecurity risks are understood — its assets, its suppliers, and the improvements its own operations reveal.

Protect

PR

Subcategories claimed
20 of 22 — 91%
Controls claiming them
27 of 78
What the function asks for
Safeguards to manage the organization’s cybersecurity risks are used — access, training, data, platforms and infrastructure resilience.

Detect

DE

Subcategories claimed
11 of 11 — 100%
Controls claiming them
13 of 78
What the function asks for
Possible cybersecurity attacks and compromises are found and analyzed.

Respond

RS

Subcategories claimed
13 of 13 — 100%
Controls claiming them
12 of 78
What the function asks for
Actions regarding a detected cybersecurity incident are taken — management, analysis, communication and mitigation.

Recover

RC

Subcategories claimed
8 of 8 — 100%
Controls claiming them
9 of 78
What the function asks for
Assets and operations affected by a cybersecurity incident are restored, and the restoration is communicated.

Every figure above is counted off the catalog’s own csf arrays against the subcategory register, not off a restatement of them. 78 of the framework’s controls carry at least one citation; 13 subcategories carry none.

The Register

Every Subcategory, Claimed or Not.

The uncited rows are the point. A crosswalk that lists only what it covers cannot be checked, because the identifiers it misses appear nowhere in it. Each subcategory below is either linked to the controls that claim it or marked as claimed by nothing.

Govern

GV · 22 of 31 subcategories · 30 controls

The organization’s cybersecurity risk management strategy, expectations and policy are established, communicated and monitored.

Organizational Context

GV.OC · 4 of 5 claimed
  • GV.OC-01
    The organizational mission is understood and informs cybersecurity risk management.
  • GV.OC-02
    Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered.
    Claimed by nothing in this catalog.
  • GV.OC-03
    Legal, regulatory and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
  • GV.OC-04
    Critical objectives, capabilities and services that external stakeholders depend on or expect from the organization are understood and communicated.
  • GV.OC-05
    Outcomes, capabilities and services that the organization depends on are understood and communicated.

Risk Management Strategy

GV.RM · 4 of 7 claimed
  • GV.RM-01
    Risk management objectives are established and agreed to by organizational stakeholders.
  • GV.RM-02
    Risk appetite and risk tolerance statements are established, communicated and maintained.
  • GV.RM-03
    Cybersecurity risk management activities and outcomes are included in enterprise risk management processes.
  • GV.RM-04
    Strategic direction that describes appropriate risk response options is established and communicated.
    Claimed by nothing in this catalog.
  • GV.RM-05
    Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties.
    Claimed by nothing in this catalog.
  • GV.RM-06
    A standardized method for calculating, documenting, categorizing and prioritizing cybersecurity risks is established and communicated.
  • GV.RM-07
    Strategic opportunities — positive risks — are characterized and included in organizational cybersecurity risk discussions.
    Claimed by nothing in this catalog.

Roles, Responsibilities and Authorities

GV.RR · 3 of 4 claimed
  • GV.RR-01
    Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical and continually improving.
  • GV.RR-02
    Roles, responsibilities and authorities related to cybersecurity risk management are established, communicated, understood and enforced.
  • GV.RR-03
    Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities and policies.
    Claimed by nothing in this catalog.
  • GV.RR-04
    Cybersecurity is included in human resources practices.

Policy

GV.PO · 1 of 2 claimed
  • GV.PO-01
    Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy and priorities, and is communicated and enforced.
  • GV.PO-02
    Policy for managing cybersecurity risks is reviewed, updated, communicated and enforced to reflect changes in requirements, threats, technology and organizational mission.
    Claimed by nothing in this catalog.

Oversight

GV.OV · 3 of 3 claimed
  • GV.OV-01
    Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction.
  • GV.OV-02
    The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks.
  • GV.OV-03
    Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed.

Cybersecurity Supply Chain Risk Management

GV.SC · 7 of 10 claimed
  • GV.SC-01
    A cybersecurity supply chain risk management program, strategy, objectives, policies and processes are established and agreed to by organizational stakeholders.
  • GV.SC-02
    Cybersecurity roles and responsibilities for suppliers, customers and partners are established, communicated and coordinated internally and externally.
    Claimed by nothing in this catalog.
  • GV.SC-03
    Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment and improvement processes.
    Claimed by nothing in this catalog.
  • GV.SC-04
    Suppliers are known and prioritized by criticality.
  • GV.SC-05
    Requirements to address cybersecurity risks in supply chains are established, prioritized and integrated into contracts and other agreements with suppliers and other relevant third parties.
    Claimed by nothing in this catalog.
  • GV.SC-06
    Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships.
  • GV.SC-07
    The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to and monitored over the course of the relationship.
  • GV.SC-08
    Relevant suppliers and other third parties are included in incident planning, response and recovery activities.
  • GV.SC-09
    Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle.
  • GV.SC-10
    Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement.

Identify

ID · 19 of 21 subcategories · 37 controls

The organization’s current cybersecurity risks are understood — its assets, its suppliers, and the improvements its own operations reveal.

Asset Management

ID.AM · 7 of 7 claimed
  • ID.AM-01
    Inventories of hardware managed by the organization are maintained.
  • ID.AM-02
    Inventories of software, services and systems managed by the organization are maintained.
  • ID.AM-03
    Representations of the organization’s authorized network communication and internal and external network data flows are maintained.
  • ID.AM-04
    Inventories of services provided by suppliers are maintained.
  • ID.AM-05
    Assets are prioritized based on classification, criticality, resources and impact on the mission.
  • ID.AM-07
    Inventories of data and corresponding metadata for designated data types are maintained.
  • ID.AM-08
    Systems, hardware, software, services and data are managed throughout their life cycles.

Risk Assessment

ID.RA · 8 of 10 claimed
  • ID.RA-01
    Vulnerabilities in assets are identified, validated and recorded.
  • ID.RA-02
    Cyber threat intelligence is received from information sharing forums and sources.
  • ID.RA-03
    Internal and external threats to the organization are identified and recorded.
  • ID.RA-04
    Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded.
  • ID.RA-05
    Threats, vulnerabilities, likelihoods and impacts are used to understand inherent risk and inform risk response prioritization.
  • ID.RA-06
    Risk responses are chosen, prioritized, planned, tracked and communicated.
  • ID.RA-07
    Changes and exceptions are managed, assessed for risk impact, recorded and tracked.
    Claimed by nothing in this catalog.
  • ID.RA-08
    Processes for receiving, analyzing and responding to vulnerability disclosures are established.
    Claimed by nothing in this catalog.
  • ID.RA-09
    The authenticity and integrity of hardware and software are assessed prior to acquisition and use.
  • ID.RA-10
    Critical suppliers are assessed prior to acquisition.

Improvement

ID.IM · 4 of 4 claimed
  • ID.IM-01
    Improvements are identified from evaluations.
  • ID.IM-02
    Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties.
  • ID.IM-03
    Improvements are identified from execution of operational processes, procedures and activities.
  • ID.IM-04
    Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained and improved.

Protect

PR · 20 of 22 subcategories · 27 controls

Safeguards to manage the organization’s cybersecurity risks are used — access, training, data, platforms and infrastructure resilience.

Identity Management, Authentication and Access Control

PR.AA · 6 of 6 claimed
  • PR.AA-01
    Identities and credentials for authorized users, services and hardware are managed by the organization.
  • PR.AA-02
    Identities are proofed and bound to credentials based on the context of interactions.
  • PR.AA-03
    Users, services and hardware are authenticated.
  • PR.AA-04
    Identity assertions are protected, conveyed and verified.
  • PR.AA-05
    Access permissions, entitlements and authorizations are defined in a policy, managed, enforced and reviewed, and incorporate least privilege and separation of duties.
  • PR.AA-06
    Physical access to assets is managed, monitored and enforced commensurate with risk.

Awareness and Training

PR.AT · 2 of 2 claimed
  • PR.AT-01
    Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.
  • PR.AT-02
    Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind.

Data Security

PR.DS · 3 of 4 claimed
  • PR.DS-01
    The confidentiality, integrity and availability of data-at-rest are protected.
  • PR.DS-02
    The confidentiality, integrity and availability of data-in-transit are protected.
  • PR.DS-10
    The confidentiality, integrity and availability of data-in-use are protected.
    Claimed by nothing in this catalog.
  • PR.DS-11
    Backups of data are created, protected, maintained and tested.

Platform Security

PR.PS · 5 of 6 claimed
  • PR.PS-01
    Configuration management practices are established and applied.
  • PR.PS-02
    Software is maintained, replaced and removed commensurate with risk.
  • PR.PS-03
    Hardware is maintained, replaced and removed commensurate with risk.
  • PR.PS-04
    Log records are generated and made available for continuous monitoring.
  • PR.PS-05
    Installation and execution of unauthorized software are prevented.
  • PR.PS-06
    Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle.
    Claimed by nothing in this catalog.

Technology Infrastructure Resilience

PR.IR · 4 of 4 claimed
  • PR.IR-01
    Networks and environments are protected from unauthorized logical access and usage.
  • PR.IR-02
    The organization’s technology assets are protected from environmental threats.
  • PR.IR-03
    Mechanisms are implemented to achieve resilience requirements in normal and adverse situations.
  • PR.IR-04
    Adequate resource capacity to ensure availability is maintained.

Detect

DE · 11 of 11 subcategories · 13 controls

Possible cybersecurity attacks and compromises are found and analyzed.

Continuous Monitoring

DE.CM · 5 of 5 claimed
  • DE.CM-01
    Networks and network services are monitored to find potentially adverse events.
  • DE.CM-02
    The physical environment is monitored to find potentially adverse events.
  • DE.CM-03
    Personnel activity and technology usage are monitored to find potentially adverse events.
  • DE.CM-06
    External service provider activities and services are monitored to find potentially adverse events.
  • DE.CM-09
    Computing hardware and software, runtime environments and their data are monitored to find potentially adverse events.

Adverse Event Analysis

DE.AE · 6 of 6 claimed
  • DE.AE-02
    Potentially adverse events are analyzed to better understand associated activities.
  • DE.AE-03
    Information is correlated from multiple sources.
  • DE.AE-04
    The estimated impact and scope of adverse events are understood.
  • DE.AE-06
    Information on adverse events is provided to authorized staff and tools.
  • DE.AE-07
    Cyber threat intelligence and other contextual information are integrated into the analysis.
  • DE.AE-08
    Incidents are declared when adverse events meet the defined incident criteria.

Respond

RS · 13 of 13 subcategories · 12 controls

Actions regarding a detected cybersecurity incident are taken — management, analysis, communication and mitigation.

Incident Management

RS.MA · 5 of 5 claimed
  • RS.MA-01
    The incident response plan is executed in coordination with relevant third parties once an incident is declared.
  • RS.MA-02
    Incident reports are triaged and validated.
  • RS.MA-03
    Incidents are categorized and prioritized.
  • RS.MA-04
    Incidents are escalated or elevated as needed.
  • RS.MA-05
    The criteria for initiating incident recovery are applied.

Incident Analysis

RS.AN · 4 of 4 claimed
  • RS.AN-03
    Analysis is performed to establish what has taken place during an incident and the root cause of the incident.
  • RS.AN-06
    Actions performed during an investigation are recorded, and the records’ integrity and provenance are preserved.
  • RS.AN-07
    Incident data and metadata are collected, and their integrity and provenance are preserved.
  • RS.AN-08
    An incident’s magnitude is estimated and validated.

Incident Response Reporting and Communication

RS.CO · 2 of 2 claimed
  • RS.CO-02
    Internal and external stakeholders are notified of incidents.
  • RS.CO-03
    Information is shared with designated internal and external stakeholders.

Incident Mitigation

RS.MI · 2 of 2 claimed
  • RS.MI-01
    Incidents are contained.
  • RS.MI-02
    Incidents are eradicated.

Recover

RC · 8 of 8 subcategories · 9 controls

Assets and operations affected by a cybersecurity incident are restored, and the restoration is communicated.

Incident Recovery Plan Execution

RC.RP · 6 of 6 claimed
  • RC.RP-01
    The recovery portion of the incident response plan is executed once initiated from the incident response process.
  • RC.RP-02
    Recovery actions are selected, scoped, prioritized and performed.
  • RC.RP-03
    The integrity of backups and other restoration assets is verified before using them for restoration.
  • RC.RP-04
    Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms.
  • RC.RP-05
    The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed.
  • RC.RP-06
    The end of incident recovery is declared based on criteria, and incident-related documentation is completed.

Incident Recovery Communication

RC.CO · 2 of 2 claimed
  • RC.CO-03
    Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders.
  • RC.CO-04
    Public updates on incident recovery are shared using approved methods and messaging.

Derived. Every edge is the inverse of a `csf` array in the published catalog; the denominator is the CSF 2.0 subcategory register below. What the framework takes from this source and what it declines to take is set out in sources and provenance; the controls named on this page each carry their full lineage on their own sheet.